Palo Alto Networks Security Advisories & CVEs
93 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Check if your Palo Alto device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.
Official source
Palo Alto Networks Security Advisories
Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.
Latest Palo Alto advisories
Low [CVE-2026-0289 +448] Prisma Browser: Sensitive Information Disclosure Vulnerability
Palo Alto Networks incorporated the following Chromium security fixes into our products: CVESummaryCVE-2026-13774 Use after free in ExtensionsCVE-2026-13775 Use after free in GPUCVE-2026-13776 Type Confusion in DawnCVE-2026-13777 Insufficient validation of untrusted input in iOSWebCVE-2026-13778 Use after free in WebUSBCVE-2026-13779 Use after free in ChromotingCVE-2026-13780 Insufficient validation of untrusted input in ANGLECVE-2026-13781 Insufficient validation of untrusted input in SkiaCVE-2026-13782 Use after free in BrowserCVE-2026-13783 Use after free in ViewsCVE-2026-13784 Use after free in ViewsCVE-2026-13785 Use after free in BluetoothCVE-2026-13786 Use af
Critical [CVE-2026-0288] PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic. The security risk posed by this issue is minimized when the User-ID Terminal Server Agent connectivity is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama is not impacted by this vulnerability. Affected products named by the advisory: Prisma Access.
High [CVE-2026-0277] Prisma Access Agent: Improper Certificate Validation on iOS
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
High [CVE-2026-0278] Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
High [CVE-2026-0283] PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and establish an unauthorized site-to-site VPN connection. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0284] PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0285] PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0286] PAN-OS: Authenticated Command Injection in CLI
A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.
High [CVE-2026-0287] PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to or through a dataplane interface. Repeated attempts to trigger this condition result in the firewall entering maintenance mode. Panorama is not impacted by these vulnerabilities. Affected products named by the advisory: Cloud NGFW; Prisma Access.
High [CVE-2026-0275 +529] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: CVESummaryCVE-2026-10881 Out of bounds read and write in ANGLECVE-2026-10882 Use after free in NetworkCVE-2026-10883 Type Confusion in ANGLECVE-2026-10884 Use after free in ChromecastCVE-2026-10885 Use after free in Chrome for iOSCVE-2026-10886 Use after free in FileSystemCVE-2026-10887 Use after free in ChromotingCVE-2026-10888 Use after free in Cast StreamingCVE-2026-10889 Out of bounds read in ANGLECVE-2026-10890 Use after free in CastCVE-2026-10891 Use after free in GFXCVE-2026-10892 Out of bounds write in GPUCVE-2026-10893 Use after free in ChromotingCVE-2026-10894 Use after free in PrintingCVE-2026-10895 Use after free in OzoneCVE-2026-10896 Use after free in Chrome for iOSCVE-2026-10897 Inappropriate implementation in GPUCVE-2026-10898 Sta
Medium [CVE-2026-0281] PAN-OS: Information Disclosure Vulnerability in Management Web Interface
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface
Medium [CVE-2026-0279] PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities Affected products named by the advisory: Prisma Access.
Medium [CVE-2026-0276] Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
Medium [CVE-2026-0280] PAN-OS: IPv6 Firewall Policy Bypass
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass Affected products named by the advisory: Prisma Access.
Medium [CVE-2026-0282] PAN-OS: File Deletion Vulnerability in Management Web Interface
A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
High [CVE-2026-0249] GlobalProtect App: Certificate Validation Bypass Vulnerabilities
CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities
High [CVE-2026-0250] GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway
CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway
Medium [CVE-2026-45169] Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a…
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriat
Medium [CVE-2026-45170] Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS…
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
High [CVE-2026-0273] PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI